polystella-contributor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [Credential Management Patterns]: The skill contains recipes for defining configuration schemas that include API keys and using these keys within network request headers for translation providers. While these patterns are standard for API integrations, they serve as a reminder to handle secrets securely through environment variables or secure configuration stores rather than within source code.
- [Command Execution Examples]: The documentation includes standard development commands (e.g.,
pnpm test,node packages/astro/dist/cli.js) for verifying changes. These are typical for contributor workflows and are provided as examples for manual execution. - [Indirect Prompt Injection Surface]: The skill defines a system for processing external file content through Large Language Models (LLMs) for translation purposes. This creates a surface where external data could potentially influence model behavior. 1. Ingestion points: External content enters the system via file adapters implemented in
packages/core/src/adapters/(e.g.,.xml,.html). 2. Boundary markers: The provided templates do not specify the use of delimiters or 'ignore' instructions to separate content from potential instructions within the source files. 3. Capability inventory: The translation providers perform network requests to external APIs usingfetch(e.g., inpackages/core/src/providers/). 4. Sanitization: The current recipes focus on structural parsing logic and do not detail content sanitization strategies for the LLM interaction.
Audit Metadata